Skip to content

Security: xyz2b/weave-ai-runtime

Security

SECURITY.md

Security Policy

English | 简体中文

Supported Versions

This repository is under active development. Security fixes are expected to land on the current main development line rather than on multiple maintained release branches.

Reporting a Vulnerability

Please do not open a public issue for an unpatched vulnerability. Instead:

  1. use a private maintainer contact path if one is available to you
  2. use GitHub Security Advisories if the repository has them enabled
  3. include reproduction steps, impact, and any suggested mitigation

What to Expect

Maintainers will try to:

  • acknowledge the report
  • reproduce the issue
  • determine impact and fix priority
  • coordinate disclosure after a fix or mitigation is ready

Scope Notes

When reporting, clarify whether the issue affects:

  • runtime core behavior
  • package composition
  • host or permission integration
  • examples or developer tooling only

There aren't any published security advisories